[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82593-en":3,"doc-seo-82593-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82593,34359740700684,"Finn","https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487",8,"Research & Report","Distributed Containment of a Compromised Agent through Repulsive Cages","UAV swarms and cyber-physical multi-agent systems need coordinated motion and distributed autonomy, yet remain vulnerable when a legitimate agent is hijacked through adversarial high-level commands. Instead of focusing on detection, the framework leverages independent low-level collision-avoidance layers that stay active under high-level compromise. Defender agents shape a repulsive field using their geometric configuration to keep the target within an admissible region and, when needed, guide it to a destination. The interaction is formulated as an online Stackelberg game with exact geometric characterization, then extended to a fully distributed approximation with provable sublinear dynamic-regret guarantees.","Distributed Containment of a Compromised Agent  \nthrough Repulsive Cages  \nLuigi Petruzziello 1 , Camilla Fioravanti 1∗, and Gabriele Oliva 1  \narXiv :2607 .01230v1 [ ee ss . SY] 1 Jul 2026  \nAbstract—UAV swarms and cyber-physical multi-agent systems are increasingly deployed in safety-critical missions that require coordinated motion, distributed decision making, and autonomy. A major security risk arises when a legitimate agent is hijacked and driven by adversarial high-level commands. Rather than focusing on detection and isolation of malicious agents, we exploit a structural property common in autonomous platforms: lowlevel collision-avoidance modules are typically implemented as independent safety layers and may remain active even under high-level compromise. Building on this property, we propose a distributed containment framework that uses the compromised agent’s uncompromised avoidance response as an indirect actuation channel. Defender agents select their geometric configuration to shape the repulsive field experienced by the target, with the goal of keeping it inside a prescribed admissible region and, when required, steering it toward a desired destination. The interaction is modeled as an online Stackelberg game in which defenders act as leaders and the adversary reacts by choosing the target command. Using support-function and normal-cone arguments, we derive an exact geometric characterization of robust one-step containment and introduce the notion of a repulsive cage. These results define a centralized Stackelberg oracle and motivate a fully distributed online approximation based on local communication and dynamic field estimation. We prove sublinear dynamic-regret bounds with respect to the centralized benchmark, quantifying the effect of network-induced estimation errors and temporal variability of the stage-wise optimum. Simulations validate the approach and corroborate the theory.  \nI. INTRODUCTION  \nCooperative multi-agent systems are now a consolidated platform in several application domains, ranging from environmental surveillance and autonomous vehicle formations to infrastructure monitoring and search-and-rescue operations [1],[2] . Many of these platforms operate according to a two-layer control architecture: a high-level command channel, which generates mission setpoints from the coordination logic, and a low-level safety layer, typically implemented in hardware or firmware, which automatically handles critical functions such as collision avoidance through pairwise repulsive actions based on relative distances [3],[4] . The latter is designed to be robust and independent of the mission channel, precisely because it acts as a non-negotiable safety primitive.  \nThis architectural separation has an important security implication: a compromise of the high-level command channel, although severe, does not automatically imply control over the entire control stack of the affected agent. This is precisely the scenario considered in this work. A legitimate agent of the fleet is hijacked by an external attacker, who gains control of its mission channel and freely selects its motion setpoint, but cannot disable or rewrite the low-level layer. A motivating  \nexample is a formation of unmanned aerial vehicles in which one vehicle is hijacked: the vehicle, which we refer to asthe target, continues to automatically generate its repulsive response with respect to the other agents, which we refer to as defenders. The compromise is therefore hybrid: the highlevel command is under adversarial control, while the lowlevel response remains unaltered, and this asymmetry is the structure exploited by our approach.  \nThe objective is to keep the target inside the admissible region Ωk+1 at each time step, despite the adversarial choice of ua. The defenders cannot command the target and do not know ua a priori; their only leverage is their collective configuration. By choosing where to move, they shape the aggregate repulsive fi","cbCaikxnHg5ANWYQ","https://ap.wps.com/l/cbCaikxnHg5ANWYQ","pdf",442965,2,1,16,"English","en",105,"# Introduction\n## Two-layer control architecture and security implication\n## Indirect field shaping and containment objective\n## Stackelberg formulation and online optimization perspective","[{\"question\":\"What security scenario does the work address in autonomous multi-agent systems?\",\"answer\":\"A legitimate agent’s mission channel is hijacked by an adversary, who can choose motion setpoints, while the low-level collision-avoidance layer remains unaltered and cannot be disabled.\"},{\"question\":\"How do defender agents contain a compromised (target) agent without direct control?\",\"answer\":\"Defenders select their geometric configuration to shape the repulsive field applied by the target’s unchanged low-level avoidance module, keeping the target inside a prescribed admissible region and steering it toward a destination when required.\"},{\"question\":\"How is the interaction between defenders and adversary modeled?\",\"answer\":\"As an online Stackelberg game: defenders act as leaders by committing to configurations, and the adversary reacts by selecting the target command, producing a sequence of stage equilibria coupled through system dynamics.\"}]",1784181701,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"distributed-containment-of-a-compromised-agent-through-repulsive-cages","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/distributed-containment-of-a-compromised-agent-through-repulsive-cages/82593/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What security scenario does the work address in autonomous multi-agent systems?","Question",{"text":75,"@type":76},"A legitimate agent’s mission channel is hijacked by an adversary, who can choose motion setpoints, while the low-level collision-avoidance layer remains unaltered and cannot be disabled.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How do defender agents contain a compromised (target) agent without direct control?",{"text":80,"@type":76},"Defenders select their geometric configuration to shape the repulsive field applied by the target’s unchanged low-level avoidance module, keeping the target inside a prescribed admissible region and steering it toward a destination when required.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the interaction between defenders and adversary modeled?",{"text":84,"@type":76},"As an online Stackelberg game: defenders act as leaders by committing to configurations, and the adversary reacts by selecting the target command, producing a sequence of stage equilibria coupled through system dynamics.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]